Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\ryu.bat
- [<HKLM>\SYSTEM\ControlSet001\Services\DisplayMgr] 'ImagePath' = '%TEMP%\DisplayMgr.sys'
- '<SYSTEM32>\cmd.exe' /c sc delete ServiceController
- '<SYSTEM32>\sc.exe' delete ServiceController
- '%WINDIR%\Temp\autoexec32.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\TEMP\Tmp2163dpea893a.bat
- NtQuerySystemInformation, драйвер-обработчик: DisplayMgr.sys
- %WINDIR%\Temp\autoexec32.exe
- %WINDIR%\Temp\install.log
- %TEMP%\DisplayMgr.sys
- %WINDIR%\Temp\autoexec32.exe
- %WINDIR%\Temp\Tmp2163dpea893a.bat
- %TEMP%\DisplayMgr.sys